DocuPal — Privacy Policy

Effective Date: July 7, 2026 · Version 4.0

DocuPal is committed to protecting your privacy. This policy explains how we collect, use, store, and protect your information when you use the DocuPal application.

1. Data We Collect

Data you provide

Data we do NOT collect

2. How We Use Your Data

Document text and chat messages are used solely to produce your analysis in real time. Analysis results and history are stored only on your device, encrypted (AES-256-GCM) with keys held in the iOS Keychain. DOCX, XLSX, and CSV files are parsed entirely on-device — only the extracted text is sent for analysis.

3. Sensitive Documents

DocuPal is not a HIPAA-covered entity and is not certified for classified/government data. Submitting legal, medical, financial, or personal documents is at your discretion; document text is transmitted to third-party AI services for processing. Avoid submitting government-classified material or unnecessary sensitive identifiers.

4. Third-Party Services

Secure AWS gateway

DocuPal routes AI requests through a secure gateway we operate on Amazon Web Services (AWS), region Asia Pacific (Singapore). Extracted text is sent to the gateway over TLS 1.3; the gateway forwards it to an AI provider and returns the result. The gateway holds all provider API keys server-side and does not persist your text after the request.

AI analysis providers

Depending on availability, language, and tier, text may be sent to any of: Cerebras, Groq, Mistral AI, Google (Gemini), OpenAI, xAI (Grok), and Anthropic (Claude). Each provider's own policy governs its handling. We do not instruct any provider to retain your data beyond the request (OpenAI may retain API inputs up to 30 days for abuse monitoring). This provider list may change as we optimize the service.

OCR, translation, and read-aloud

Low-confidence images may be sent to Google Cloud Vision for OCR. Translation uses Apple's on-device framework where available, with Google Translate as a fallback. Read-aloud may use Amazon Polly and Google Cloud Text-to-Speech (which receive the text), with Apple's on-device speech as a fallback.

Configuration & integrity

We use Google Firebase Remote Config to deliver feature flags and limits; it associates an anonymous installation identifier. We use Apple DeviceCheck (a per-device flag, no personal data) to prevent trial abuse. We use no advertising, analytics, or tracking SDKs.

5. Security

6. Data Retention & Your Rights

All data lives on your device until you delete it (per-item, or Settings → Reset App Data). Nothing is retained on our servers after processing. You may exercise access, correction, deletion, portability, and consent-withdrawal rights (GDPR, PDPA, CCPA and similar) by using in-app controls or contacting us.

7. International Transfers

Text is transmitted first to our AWS gateway in Singapore, then to third-party provider servers that may be outside your country. Transfers are protected by TLS 1.3, server-side key custody, minimal data transmission, and no retention instruction. EU transfers rely on Standard Contractual Clauses as applicable to AWS and the providers.

8. Children

DocuPal is not directed at children under 13 (or 16 in the EU). We do not knowingly collect data from children. Minors aged 13–18 should use the app only with parental consent and supervision.

9. Changes

We may update this policy from time to time. Material changes are communicated in-app and may require re-consent. The version and effective date above will be updated accordingly.

10. Contact

Data-protection contact: srinivassane.r@outlook.com. We aim to respond within 30 days.


DocuPal uses AI and can make mistakes. It is an informational tool only and does not provide legal, medical, financial, or other professional advice. Always verify important information and consult a qualified professional before making decisions. Governing law: Singapore.